> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mcpjam.com/llms.txt
> Use this file to discover all available pages before exploring further.

# What the caller may do here

> Role, gate state, plan limits and a set of derived booleans — so an agent on a static surface can check before it acts instead of attempting a write and reading the failure.

Descriptive, never authoritative: see the schema.



## OpenAPI

````yaml /reference/openapi.json get /projects/{projectId}/capabilities
openapi: 3.1.0
info:
  title: MCPJam API
  version: 1.0.0-preview
  description: >-
    Programmatic access to MCP servers saved in your MCPJam projects — live
    diagnostics (validate, inspect, export) and operations: call tools, render
    prompts, run eval suites asynchronously and poll their results, and import
    OAuth tokens.


    **The API is in preview**: the surface may change while we finish the
    design. Error `code` values are stable; error `message` strings are not.
    Write clients that ignore unknown response fields.
  contact:
    name: MCPJam
    url: https://github.com/MCPJam/inspector/issues
servers:
  - url: https://app.mcpjam.com/api/v1
    description: Hosted MCPJam
security:
  - bearerAuth: []
tags:
  - name: Hosts
    description: >-
      Project hosts: named model + capability profiles you run chats and eval
      suites against.
  - name: Environments
    description: >-
      Project environments: named, live-editable execution bundles (one host, an
      optional standalone server group, optionally pinned skills and plugin
      versions) that eval suites and journeys run against. Distinct from Sandbox
      images, which are Computer base images. Reads require project membership;
      every write requires project admin.
  - name: Plugins
    description: >-
      Agent Plugins imported into a project — read-only inventory and version
      detail.
  - name: Sandbox images
    description: >-
      Custom Computer images: a digest-pinned Dockerfile built into an immutable
      image your project's computers boot from.
  - name: Server diagnostics
    description: Connect-level health checks against a saved MCP server.
  - name: Primitives
    description: 'The server''s MCP primitives: tools, prompts, and resources.'
  - name: Export
    description: Full-server snapshots for diffing and CI.
  - name: Execution
    description: 'Run the server''s primitives: call tools, render prompts.'
  - name: Eval runs
    description: >-
      Asynchronous eval suite runs: create with 202, poll status, iterations,
      and traces.
  - name: Server connections
    description: >-
      Connect an MCP server URL to a project, authorizing in a browser when the
      server requires it.
  - name: OAuth
    description: 'Bring-your-own OAuth: import externally obtained tokens for a server.'
  - name: Chatboxes
    description: >-
      Read-only access to the chatboxes published from a project: listing,
      settings, attached servers, and share links.
  - name: Catalog
    description: >-
      Discover the resources the other routes operate on: your account,
      projects, servers, eval suites, and chat sessions.
  - name: Tunnels
    description: >-
      Relay tunnels that expose local MCP servers through a public URL,
      registered as first-class project servers (the `mcpjam tunnel` CLI flow).
  - name: Agent
    description: >-
      Headless agent turns over the public API: send a message history, the
      server runs one assistant turn with project-scoped workspace tools (eval
      reads + suite creation) on a pinned hosted model, and returns the reply
      plus created-resource references.
  - name: Swarms
    description: >-
      Personas, journeys and swarm containers — the authoring half of Swarms —
      plus the model-backed generation that drafts them.
  - name: Swarm runs
    description: >-
      Launching journeys and reading what they produced. Launching SPENDS — see
      the per-operation notes.
  - name: Swarm insights
    description: >-
      What a swarm run revealed. The scorecard and findings are deterministic
      and free; requesting wave insights runs models and draws on your shared
      daily ledger.
  - name: User testing
    description: >-
      Publishing an environment for real visitors, and controlling who can reach
      it. Several of these NARROW access and take effect immediately.
paths:
  /projects/{projectId}/capabilities:
    parameters:
      - $ref: '#/components/parameters/projectId'
    get:
      tags:
        - Projects
      summary: What the caller may do here
      description: >-
        Role, gate state, plan limits and a set of derived booleans — so an
        agent on a static surface can check before it acts instead of attempting
        a write and reading the failure.


        Descriptive, never authoritative: see the schema.
      operationId: getProjectCapabilities
      responses:
        '200':
          description: The caller's capabilities in this project.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProjectCapabilities'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  parameters:
    projectId:
      name: projectId
      in: path
      required: true
      description: ID of the hosted project that contains the server.
      schema:
        type: string
  schemas:
    ProjectCapabilities:
      type: object
      required:
        - projectId
        - organizationId
        - role
        - projectRole
        - surface
        - features
        - plan
        - can
      description: >-
        What the caller may do in this project, asked BEFORE they try it.


        **A planning aid, not a gate.** Every enforcement point is unchanged:
        the write path checks roles and the beta flag inside the platform
        regardless of what this returned a second earlier. A caller that reads a
        `true` here and races a flag flip gets the same clean `403` it would
        have got without asking. Nothing may consult this INSTEAD of its own
        check.


        It exists because every agent surface MCPJam ships is static — one MCP
        tool catalog built with no organization in hand, a CLI command tree
        fixed at install — so an agent planning a task otherwise has to attempt
        the write and read the failure. By then it has usually already told a
        human what it was about to do.
      properties:
        projectId:
          type: string
        organizationId:
          type:
            - string
            - 'null'
        role:
          type: string
          description: >-
            The caller's ORGANIZATION role: `guest`, `member`, `admin` or
            `owner`. This is what the platform's role checks rank; a project
            grant does not raise it.
        projectRole:
          type: string
          description: '`admin` or `editor`, when the caller holds a project grant.'
        surface:
          type: string
          description: >-
            Which channel we resolved this request to arrive on. Echoed so an
            agent can confirm it is labelled the way it expects — a CLI showing
            up as `rest` means its user agent is not reaching us.
        features:
          type: object
          required:
            - sandboxes
          properties:
            sandboxes:
              type: object
              required:
                - enabled
                - mode
                - enforced
              properties:
                enabled:
                  type: boolean
                mode:
                  type: string
                  description: >-
                    `off` | `dark` | `enforce`. Only `enforce` turns a disabled
                    flag into a refusal; in `dark` the platform logs what it
                    would have blocked and lets the write through.
                  enum:
                    - 'off'
                    - dark
                    - enforce
                enforced:
                  type: boolean
                reason:
                  type: string
        plan:
          oneOf:
            - type: object
              required:
                - name
                - limits
                - features
              properties:
                name:
                  type: string
                limits:
                  type: object
                  additionalProperties: true
                features:
                  type: object
                  additionalProperties: true
            - type: 'null'
        can:
          type: object
          required:
            - readSwarms
            - readUserTesting
            - writeSwarms
            - launchJourneyRun
            - cancelJourneyRun
            - publishUserTestingScenario
            - unpublishUserTestingScenario
            - changeUserTestingExposure
            - manageUserTestingGuestExecution
            - requestInsights
          description: >-
            The booleans to branch on, derived server-side rather than left for
            each caller to re-derive from `role` plus flag state.
          properties:
            readSwarms:
              type: boolean
            readUserTesting:
              type: boolean
            writeSwarms:
              type: boolean
              description: Authoring personas, journeys and swarms.
            launchJourneyRun:
              type: boolean
            cancelJourneyRun:
              type: boolean
              description: >-
                Stays TRUE for an organization that has lost the beta. Losing
                the feature is exactly when stopping a run matters most.
            publishUserTestingScenario:
              type: boolean
              description: Project admin, and behind the beta gate.
            unpublishUserTestingScenario:
              type: boolean
              description: Project admin, NOT gated — same reasoning as cancelling a run.
            changeUserTestingExposure:
              type: boolean
              description: >-
                Mode changes, member invites and removals, link rotation,
                renames — the controls an ordinary MEMBER can use, none of them
                gated. Guest execution is not covered here; it needs admin and
                has its own key.
            manageUserTestingGuestExecution:
              type: boolean
              description: The guest-execution spend caps. Project admin, ungated.
            requestInsights:
              type: boolean
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
          description: >-
            Stable, machine-readable error code. New codes may be added over
            time; treat unknown codes as non-retryable failures unless the HTTP
            status says otherwise.
          enum:
            - UNAUTHORIZED
            - FORBIDDEN
            - NOT_FOUND
            - CONFLICT
            - VALIDATION_ERROR
            - RATE_LIMITED
            - FEATURE_NOT_SUPPORTED
            - SERVER_UNREACHABLE
            - TIMEOUT
            - OAUTH_REQUIRED
            - INTERNAL_ERROR
        message:
          type: string
          description: >-
            Human-readable description. May change between releases — don't
            match on it.
        details:
          type: object
          description: Optional, unstructured context bag.
          additionalProperties: true
  responses:
    Unauthorized:
      description: >-
        Missing, invalid, revoked, or orphaned key (`UNAUTHORIZED`) — or the
        **target MCP server** needs an OAuth grant (`OAUTH_REQUIRED`), which is
        a property of the server, not your key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          examples:
            badKey:
              summary: Invalid or revoked key
              value:
                code: UNAUTHORIZED
                message: Invalid API key
            oauthRequired:
              summary: Target server needs an OAuth grant
              value:
                code: OAUTH_REQUIRED
                message: Server requires OAuth authorization
    Forbidden:
      description: Key is valid but not allowed to do this.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: FORBIDDEN
            message: You do not have access to this project
    NotFound:
      description: Unknown project, server, or resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: NOT_FOUND
            message: Server not found
    RateLimited:
      description: >-
        Per-key rate limit exceeded (60 requests/minute sustained, bursts up to
        10). Honor `Retry-After` and back off with jitter.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: RATE_LIMITED
            message: API key rate limit exceeded. Slow down and retry.
    InternalError:
      description: Something failed on MCPJam's side.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: INTERNAL_ERROR
            message: Unexpected internal error
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        MCPJam API key (`sk_…`). Create one at [Settings → API
        keys](https://app.mcpjam.com/settings/api-keys). Guest sessions cannot
        use the API, and API keys cannot manage other API keys.

````